Zohocorp
zohocorp
550 CVEs • 69 products
Products (69)
Click to collapseToggle
Products (69)
Click to collapse
CVEs (550)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Zohocorp 1Manageengine Adselfservice Plus Jun 17, 2026 May 14, 2025 N/A· v4 8.1 HIGH· v3 N/A· v2 Zohocorp ManageEngine ADSelfService Plus versions 6513 and prior are vulnerable to authenticated SQL injection in the MFA reports. |
1Zohocorp 3Manageengine Servicedesk Plus Manageengine Servicedesk Plus MspManageengine Supportcentre PlusJun 17, 2026 Mar 21, 2025 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Zohocorp ManageEngine ServiceDesk Plus versions below 14920 , ServiceDesk Plus MSP and SupportCentre Plus versions below 14910 are vulnerable to Stored XSS in the task feature. |
1Zohocorp 1Manageengine Adselfservice Plus Jun 17, 2026 Mar 3, 2025 N/A· v4 8.1 HIGH· v3 N/A· v2 Zohocorp ManageEngine ADSelfService Plus versions 6510 and below are vulnerable to account takeover due to the session mishandling. Valid account holders in the setup only have the potential to exploit this bug. |
1Zohocorp 1Manageengine Endpoint Central Jun 17, 2026 Feb 5, 2025 N/A· v4 4.3 MEDIUM· v3 N/A· v2 ManageEngine Endpoint Central versions before 11.3.2440.09 are vulnerable to IDOR vulnerability which allows the attacker to change the username in the chat. |
1Zohocorp 1Manageengine Applications Manager Jun 17, 2026 Jan 29, 2025 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Zohocorp ManageEngine Applications Manager versions 174000 and prior are vulnerable to the incorrect authorization in the update user function. |
1Zohocorp 1Manageengine Analytics Plus Jun 17, 2026 Nov 27, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 Zohocorp ManageEngine Analytics Plus versions below 6100 are vulnerable to authenticated sensitive data exposure which allows the users to retrieve sensitive tokens associated to the org-admin account. |
Zohocorp ManageEngine ADAudit Plus versions below 8123 are vulnerable to SQL Injection in the reports module. |
1Zohocorp 1Manageengine Sharepoint Manager Plus Jun 17, 2026 Nov 8, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 Zohocorp ManageEngine SharePoint Manager Plus versions 4503 and prior are vulnerable to authenticated XML External Entity (XXE) in the Management option. |
1Zohocorp 1Manageengine Admanager Plus Jun 17, 2026 Nov 8, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Zohocorp ManageEngine ADManager Plus versions 7203 and prior are vulnerable to Privilege Escalation in the Modify Computers option. |
1Zohocorp 1Manageengine Endpoint Central Jun 17, 2026 Nov 7, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Zohocorp ManageEngine EndPoint Central versions 11.3.2416.21 and below, 11.3.2428.9 and below are vulnerable to Arbitrary File Deletion in the agent installed machines. |
1Zohocorp 1Manageengine Exchange Reporter Plus Jun 17, 2026 Nov 5, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Zohocorp ManageEngine Exchange Reporter Plus versions 5718 and prior are vulnerable to authenticated SQL Injection in reports module. |
Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in Technician reports option. |
1Zohocorp 1Manageengine Admanager Plus Jun 17, 2026 Nov 4, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Zohocorp ManageEngine ADManager Plus versions 7241 and prior are vulnerable to SQL Injection in Archived Audit Report. |
Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in the technician reports feature. |
1Zohocorp 1Manageengine Endpoint Central Jun 17, 2026 Aug 30, 2024 N/A· v4 8.3 HIGH· v3 N/A· v2 Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability while isolating the devices.This issue affects Endpoint Central: before 11.3.2406.08 and before 11.3.2400.15 |
1Zohocorp 1Manageengine Exchange Reporter Plus Jun 17, 2026 Aug 30, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 Zohocorp ManageEngine Exchange Reporter Plus versions before 5715 are vulnerable to SQL Injection in the reports module. |
1Zohocorp 2Manageengine Pam360 Manageengine Password Manager ProJun 17, 2026 Aug 28, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Zohocorp ManageEngine Password Manager Pro versions before 12431 and ManageEngine PAM360 versions before 7001 are affected by authenticated SQL Injection vulnerability via a global search option. |
1Zohocorp 3Manageengine Servicedesk Plus Manageengine Servicedesk Plus MspManageengine Supportcenter PlusJun 17, 2026 Aug 23, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 An Stored Cross-site Scripting vulnerability in request module affects Zohocorp ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP and SupportCenter Plus.This issue affects ServiceDesk Plus versions: through 14810; Serv...Show more |
1Zohocorp 3Manageengine Servicedesk Plus Manageengine Servicedesk Plus MspManageengine Supportcenter PlusJun 17, 2026 Aug 23, 2024 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability in remote office deploy configurations.This issue affects Endpoint Central: before 11.3.2416.04 and before 11.3.2400.25. |
Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to the authenticated SQL injection in extranet lockouts report option. |